Record summary

CVE-2011-0167 has a selected CVSS score of 4.3; EIP currently links 1 catalogued exploit.

Description

The windows functionality in WebKit in Apple Safari before 5.0.4 allows remote attackers to bypass the Same Origin Policy, and force the upload of arbitrary local files from a client computer, via a crafted web site.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBWebKit 1.2.x - Local Webpage Cross Domain Information DisclosureExploitDB exploitby Aaron SigelNot analyzed1 file
ExploitDB

PoC details

References

5